{"id":"CVE-2021-42836","aliases":["CVE-2021-42248","GHSA-c9gm-7rfj-8w5h","GHSA-ppj4-34rq-v8j9","GO-2021-0265"],"url":"https://o3.security/vulnerability/CVE-2021-42836","summary":"Duplicate Advisory: ReDoS via crafted JSON input in GJSON","details":"GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.","published":"2021-10-22T18:15:14.897Z","modified":"2026-07-09T00:37:31.974485Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Go","name":"github.com/tidwall/gjson","fixedVersion":"1.9.3"}],"fix":{"url":"https://github.com/tidwall/gjson/commit/590010fdac311cc8990ef5c97448d4fec8f29944","label":"tidwall/gjson@590010f"},"references":[{"type":"ADVISORY","url":"https://github.com/tidwall/gjson/compare/v1.9.2...v1.9.3"},{"type":"REPORT","url":"https://github.com/tidwall/gjson/issues/236"},{"type":"FIX","url":"https://github.com/tidwall/gjson/commit/590010fdac311cc8990ef5c97448d4fec8f29944"},{"type":"FIX","url":"https://github.com/tidwall/gjson/commit/77a57fda87dca6d0d7d4627d512a630f89a91c96"},{"type":"FIX","url":"https://github.com/tidwall/gjson/issues/237"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:37:31.974485Z"}}